PT-2019-7545 · Cjson · Cjson
Marco Grassi
·
Published
2019-04-29
·
Updated
2025-07-22
·
CVE-2016-10749
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
cJSON versions prior to 2016-10-02
Description
The issue is related to a buffer over-read in the
parse string function in cJSON.c. This occurs when processing a string that starts with a " character and ends with a character.Recommendations
For versions prior to 2016-10-02, update to a version released after 2016-10-02 to resolve the issue.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cjson